mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-06-17 19:33:37 +00:00
Remove beta tags from APIs
This commit is contained in:
@ -19,12 +19,9 @@ ms.topic: article
|
|||||||
# Add or Remove Machine Tags API
|
# Add or Remove Machine Tags API
|
||||||
|
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
This API adds or remove tag to a specific machine.
|
||||||
|
|
||||||
[!include[Prerelease information](prerelease.md)]
|
|
||||||
|
|
||||||
- Adds or remove tag to a specific machine.
|
|
||||||
|
|
||||||
## Permissions
|
## Permissions
|
||||||
One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md)
|
One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md)
|
||||||
|
@ -20,8 +20,6 @@ ms.topic: article
|
|||||||
**Applies to:**
|
**Applies to:**
|
||||||
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
|
||||||
|
|
||||||
Represents an alert entity in Windows Defender ATP.
|
Represents an alert entity in Windows Defender ATP.
|
||||||
|
|
||||||
# Methods
|
# Methods
|
||||||
|
@ -14,18 +14,16 @@ manager: dansimp
|
|||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.date: 12/08/2017
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Collect investigation package API
|
# Collect investigation package API
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
|
||||||
|
|
||||||
Collect investigation package from a machine.
|
Collect investigation package from a machine.
|
||||||
|
|
||||||
[!include[Machine actions note](machineactionsnote.md)]
|
|
||||||
|
|
||||||
## Permissions
|
## Permissions
|
||||||
One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md)
|
One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md)
|
||||||
|
@ -21,7 +21,7 @@ ms.date: 04/11/2019
|
|||||||
**Applies to:**
|
**Applies to:**
|
||||||
- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease<EFBFBD>information](prerelease.md)]
|
[!include[Prerelease information](prerelease.md)]
|
||||||
|
|
||||||
>[!NOTE]
|
>[!NOTE]
|
||||||
> Secure score is now part of Threat & Vulnerability Management as Configuration score. We’ll keep the secure score page available for a few weeks. View the [Secure score](https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-atp/overview-secure-score-windows-defender-advanced-threat-protection) page.
|
> Secure score is now part of Threat & Vulnerability Management as Configuration score. We’ll keep the secure score page available for a few weeks. View the [Secure score](https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-atp/overview-secure-score-windows-defender-advanced-threat-protection) page.
|
||||||
|
@ -20,7 +20,7 @@ ms.topic: article
|
|||||||
**Applies to:**
|
**Applies to:**
|
||||||
- [Windows Defender Advanced Threat Protection Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
- [Windows Defender Advanced Threat Protection Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease<EFBFBD>information](prerelease.md)]
|
[!include[Prerelease information](prerelease.md)]
|
||||||
|
|
||||||
This section guides you through the steps you need to take to configure Threat & Vulnerability Management's integration with Microsoft Intune or Microsoft System Center Configuration Manager (SCCM) for a seamless collaboration of issue remediation.
|
This section guides you through the steps you need to take to configure Threat & Vulnerability Management's integration with Microsoft Intune or Microsoft System Center Configuration Manager (SCCM) for a seamless collaboration of issue remediation.
|
||||||
|
|
||||||
|
@ -23,7 +23,7 @@ ms.date: 02/28/2019
|
|||||||
|
|
||||||
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease<EFBFBD>information](prerelease.md)]
|
[!include[Prerelease information](prerelease.md)]
|
||||||
|
|
||||||
## Before you begin
|
## Before you begin
|
||||||
To experience the full Microsoft Threat Experts preview capability in Windows Defender ATP, you need to have a valid Premier customer service and support account. However, Premier charges will not be incurred during the preview.
|
To experience the full Microsoft Threat Experts preview capability in Windows Defender ATP, you need to have a valid Premier customer service and support account. However, Premier charges will not be incurred during the preview.
|
||||||
|
@ -14,16 +14,12 @@ manager: dansimp
|
|||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.date: 12/08/2017
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Create alert from event API
|
# Create alert from event API
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
|
||||||
|
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
|
||||||
|
|
||||||
|
|
||||||
Enables using event data, as obtained from the [Advanced Hunting](run-advanced-query-api.md) for creating a new alert entity.
|
Enables using event data, as obtained from the [Advanced Hunting](run-advanced-query-api.md) for creating a new alert entity.
|
||||||
|
@ -21,10 +21,9 @@ ms.topic: article
|
|||||||
**Applies to:**
|
**Applies to:**
|
||||||
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
|
||||||
|
|
||||||
>[!Note]
|
>[!Note]
|
||||||
> Currently this API is supported only for AppOnly context requests. (See [Get access with application context](exposed-apis-create-app-webapp.md) for more information)
|
> Currently this API is only supported for AppOnly context requests. (See [Get access with application context](exposed-apis-create-app-webapp.md) for more information)
|
||||||
|
|
||||||
|
|
||||||
- Deletes an Indicator entity by ID.
|
- Deletes an Indicator entity by ID.
|
||||||
|
@ -19,12 +19,11 @@ ms.date: 09/03/2018
|
|||||||
|
|
||||||
# Use Windows Defender ATP APIs
|
# Use Windows Defender ATP APIs
|
||||||
|
|
||||||
**Applies to:** [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://wincom.blob.core.windows.net/documents/Windows10_Commercial_Comparison.pdf)
|
**Applies to:**
|
||||||
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
> Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-exposedapis-abovefoldlink)
|
> Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-exposedapis-abovefoldlink)
|
||||||
|
|
||||||
[!include[Prerelease information](prerelease.md)]
|
|
||||||
|
|
||||||
|
|
||||||
This page describes how to create an application to get programmatic access to Windows Defender ATP on behalf of a user.
|
This page describes how to create an application to get programmatic access to Windows Defender ATP on behalf of a user.
|
||||||
|
|
||||||
|
@ -19,11 +19,11 @@ ms.date: 09/03/2018
|
|||||||
|
|
||||||
# Create an app to access Windows Defender ATP without a user
|
# Create an app to access Windows Defender ATP without a user
|
||||||
|
|
||||||
**Applies to:** [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://wincom.blob.core.windows.net/documents/Windows10_Commercial_Comparison.pdf)
|
**Applies to:**
|
||||||
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
> Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-exposedapis-abovefoldlink)
|
> Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-exposedapis-abovefoldlink)
|
||||||
|
|
||||||
[!include[Prerelease information](prerelease.md)]
|
|
||||||
|
|
||||||
This page describes how to create an application to get programmatic access to Windows Defender ATP without a user.
|
This page describes how to create an application to get programmatic access to Windows Defender ATP without a user.
|
||||||
|
|
||||||
|
@ -21,8 +21,6 @@ ms.date: 09/24/2018
|
|||||||
**Applies to:**
|
**Applies to:**
|
||||||
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease information](prerelease.md)]
|
|
||||||
|
|
||||||
|
|
||||||
Full scenario using multiple APIs from Windows Defender ATP.
|
Full scenario using multiple APIs from Windows Defender ATP.
|
||||||
|
|
||||||
|
@ -14,18 +14,17 @@ manager: dansimp
|
|||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.date: 11/15/2018
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# OData queries with Windows Defender ATP
|
# OData queries with Windows Defender ATP
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease information](prerelease.md)]
|
|
||||||
|
|
||||||
- If you are not familiar with OData queries, see: [OData V4 queries](https://www.odata.org/documentation/)
|
|
||||||
|
|
||||||
- Not all properties are filterable.
|
If you are not familiar with OData queries, see: [OData V4 queries](https://www.odata.org/documentation/)
|
||||||
|
|
||||||
|
Not all properties are filterable.
|
||||||
|
|
||||||
### Properties that supports $filter:
|
### Properties that supports $filter:
|
||||||
|
|
||||||
|
@ -20,7 +20,6 @@ ms.topic: article
|
|||||||
**Applies to:**
|
**Applies to:**
|
||||||
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease information](prerelease.md)]
|
|
||||||
|
|
||||||
Represent a file entity in Windows Defender ATP.
|
Represent a file entity in Windows Defender ATP.
|
||||||
|
|
||||||
|
@ -19,11 +19,8 @@ ms.date: 07/25/2018
|
|||||||
|
|
||||||
# Find machine information by internal IP API
|
# Find machine information by internal IP API
|
||||||
|
|
||||||
[!include[Prerelease information](prerelease.md)]
|
|
||||||
|
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
|
||||||
|
|
||||||
|
|
||||||
Find a machine by internal IP.
|
Find a machine by internal IP.
|
||||||
|
@ -14,19 +14,17 @@ manager: dansimp
|
|||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.date: 12/08/2017
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Find machines by internal IP API
|
# Find machines by internal IP API
|
||||||
|
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
Find machines seen with the requested internal IP in the time range of 15 minutes prior and after a given timestamp
|
||||||
|
|
||||||
- Find machines seen with the requested internal IP in the time range of 15 minutes prior and after a given timestamp
|
The given timestamp must be in the past 30 days.
|
||||||
- The given timestamp must be in the past 30 days.
|
|
||||||
|
|
||||||
## Permissions
|
## Permissions
|
||||||
One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md)
|
One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md)
|
||||||
|
@ -14,14 +14,12 @@ manager: dansimp
|
|||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.date: 12/08/2017
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Get alert information by ID API
|
# Get alert information by ID API
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
|
||||||
|
|
||||||
Retrieves an alert by its ID.
|
Retrieves an alert by its ID.
|
||||||
|
|
||||||
|
@ -14,14 +14,13 @@ manager: dansimp
|
|||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.date: 12/08/2017
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Get alert related domain information API
|
# Get alert related domain information API
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
|
||||||
|
|
||||||
Retrieves all domains related to a specific alert.
|
Retrieves all domains related to a specific alert.
|
||||||
|
|
||||||
|
@ -14,14 +14,12 @@ manager: dansimp
|
|||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.date: 12/08/2017
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Get alert related files information API
|
# Get alert related files information API
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
|
||||||
|
|
||||||
Retrieves all files related to a specific alert.
|
Retrieves all files related to a specific alert.
|
||||||
|
|
||||||
|
@ -14,14 +14,12 @@ manager: dansimp
|
|||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.date: 12/08/2017
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Get alert related IP information API
|
# Get alert related IP information API
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
|
||||||
|
|
||||||
|
|
||||||
Retrieves all IPs related to a specific alert.
|
Retrieves all IPs related to a specific alert.
|
||||||
|
@ -14,17 +14,14 @@ manager: dansimp
|
|||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.date: 12/08/2017
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Get alert related machine information API
|
# Get alert related machine information API
|
||||||
|
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
Retrieves machine that is related to a specific alert.
|
||||||
|
|
||||||
- Retrieves machine that is related to a specific alert.
|
|
||||||
|
|
||||||
## Permissions
|
## Permissions
|
||||||
One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md)
|
One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md)
|
||||||
|
@ -14,14 +14,12 @@ manager: dansimp
|
|||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.date: 12/08/2017
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Get alert related user information API
|
# Get alert related user information API
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
|
||||||
|
|
||||||
|
|
||||||
Retrieves the user associated to a specific alert.
|
Retrieves the user associated to a specific alert.
|
||||||
|
@ -14,21 +14,20 @@ manager: dansimp
|
|||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.date: 12/08/2017
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# List alerts API
|
# List alerts API
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
Retrieves a collection of Alerts.
|
||||||
|
|
||||||
|
Supports [OData V4 queries](https://www.odata.org/documentation/).
|
||||||
|
|
||||||
- Retrieves a collection of Alerts.
|
The OData's Filter query is supported on: "Id", "IncidentId", "AlertCreationTime", "Status", "Severity" and "Category".
|
||||||
- Supports [OData V4 queries](https://www.odata.org/documentation/).
|
|
||||||
- The OData's Filter query is supported on: "Id", "IncidentId", "AlertCreationTime", "Status", "Severity" and "Category".
|
See examples at [OData queries with Windows Defender ATP](exposed-apis-odata-samples.md)
|
||||||
- See examples at [OData queries with Windows Defender ATP](exposed-apis-odata-samples.md)
|
|
||||||
|
|
||||||
## Permissions
|
## Permissions
|
||||||
One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md)
|
One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md)
|
||||||
|
@ -14,19 +14,12 @@ manager: dansimp
|
|||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.date: 12/08/2017
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Get domain related alerts API
|
# Get domain related alerts API
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
Retrieves a collection of alerts related to a given domain address.
|
Retrieves a collection of alerts related to a given domain address.
|
||||||
|
|
||||||
|
@ -14,14 +14,12 @@ manager: dansimp
|
|||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.date: 12/08/2017
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Get domain related machines API
|
# Get domain related machines API
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
|
||||||
|
|
||||||
Retrieves a collection of machines that have communicated to or from a given domain address.
|
Retrieves a collection of machines that have communicated to or from a given domain address.
|
||||||
|
|
||||||
|
@ -14,15 +14,12 @@ manager: dansimp
|
|||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.date: 12/08/2017
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Get domain statistics API
|
# Get domain statistics API
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
|
||||||
|
|
||||||
Retrieves the prevalence for the given domain.
|
Retrieves the prevalence for the given domain.
|
||||||
|
|
||||||
|
@ -14,16 +14,12 @@ manager: dansimp
|
|||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.date: 12/08/2017
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Get file information API
|
# Get file information API
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
|
||||||
|
|
||||||
|
|
||||||
Retrieves a file by identifier Sha1, Sha256, or MD5.
|
Retrieves a file by identifier Sha1, Sha256, or MD5.
|
||||||
|
|
||||||
|
@ -19,11 +19,7 @@ ms.date: 12/08/2017
|
|||||||
|
|
||||||
# Get file related alerts API
|
# Get file related alerts API
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
|
||||||
|
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
|
||||||
|
|
||||||
|
|
||||||
Retrieves a collection of alerts related to a given file hash.
|
Retrieves a collection of alerts related to a given file hash.
|
||||||
|
@ -20,10 +20,7 @@ ms.date: 12/08/2017
|
|||||||
# Get file related machines API
|
# Get file related machines API
|
||||||
|
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
|
||||||
|
|
||||||
- Retrieves a collection of machines related to a given file hash.
|
- Retrieves a collection of machines related to a given file hash.
|
||||||
|
|
||||||
|
@ -19,14 +19,7 @@ ms.date: 12/08/2017
|
|||||||
|
|
||||||
# Get file statistics API
|
# Get file statistics API
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
Retrieves the prevalence for the given file.
|
Retrieves the prevalence for the given file.
|
||||||
|
|
||||||
|
@ -19,10 +19,7 @@ ms.date: 12/08/2017
|
|||||||
|
|
||||||
# Get IP related alerts API
|
# Get IP related alerts API
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
|
||||||
|
|
||||||
Retrieves a collection of alerts related to a given IP address.
|
Retrieves a collection of alerts related to a given IP address.
|
||||||
|
|
||||||
|
@ -19,9 +19,7 @@ ms.date: 12/08/2017
|
|||||||
|
|
||||||
# Get IP related machines API
|
# Get IP related machines API
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
|
||||||
|
|
||||||
|
|
||||||
Retrieves a collection of machines that communicated with or from a particular IP.
|
Retrieves a collection of machines that communicated with or from a particular IP.
|
||||||
|
@ -19,12 +19,7 @@ ms.date: 12/08/2017
|
|||||||
|
|
||||||
# Get IP statistics API
|
# Get IP statistics API
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
Retrieves the prevalence for the given IP.
|
Retrieves the prevalence for the given IP.
|
||||||
|
|
||||||
|
@ -20,12 +20,9 @@ ms.date: 12/08/2017
|
|||||||
# Get machine by ID API
|
# Get machine by ID API
|
||||||
|
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
Retrieves a machine entity by ID.
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
|
||||||
|
|
||||||
- Retrieves a machine entity by ID.
|
|
||||||
|
|
||||||
## Permissions
|
## Permissions
|
||||||
One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md)
|
One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md)
|
||||||
|
@ -18,12 +18,9 @@ ms.date: 12/08/2017
|
|||||||
---
|
---
|
||||||
|
|
||||||
# Get machine log on users API
|
# Get machine log on users API
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
|
||||||
|
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
|
||||||
Retrieves a collection of logged on users.
|
Retrieves a collection of logged on users.
|
||||||
|
|
||||||
## Permissions
|
## Permissions
|
||||||
|
@ -18,12 +18,9 @@ ms.date: 12/08/2017
|
|||||||
---
|
---
|
||||||
|
|
||||||
# Get machine related alerts API
|
# Get machine related alerts API
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
|
||||||
|
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
|
||||||
Retrieves a collection of alerts related to a given machine ID.
|
Retrieves a collection of alerts related to a given machine ID.
|
||||||
|
|
||||||
## Permissions
|
## Permissions
|
||||||
|
@ -20,12 +20,9 @@ ms.date: 12/08/2017
|
|||||||
# Get machineAction API
|
# Get machineAction API
|
||||||
|
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
Get action performed on a machine.
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
|
||||||
|
|
||||||
- Get action performed on a machine.
|
|
||||||
|
|
||||||
## Permissions
|
## Permissions
|
||||||
One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md)
|
One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md)
|
||||||
|
@ -20,15 +20,16 @@ ms.date: 12/08/2017
|
|||||||
# List MachineActions API
|
# List MachineActions API
|
||||||
|
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
Gets collection of actions done on machines.
|
||||||
|
|
||||||
- Gets collection of actions done on machines.
|
Get MachineAction collection API supports [OData V4 queries](https://www.odata.org/documentation/).
|
||||||
- Get MachineAction collection API supports [OData V4 queries](https://www.odata.org/documentation/).
|
|
||||||
- The OData's Filter query is supported on: "Id", "Status", "MachineId", "Type", "Requestor" and "CreationDateTimeUtc".
|
The OData's Filter query is supported on: "Id", "Status", "MachineId", "Type", "Requestor" and "CreationDateTimeUtc".
|
||||||
- See examples at [OData queries with Windows Defender ATP](exposed-apis-odata-samples.md)
|
|
||||||
|
See examples at [OData queries with Windows Defender ATP](exposed-apis-odata-samples.md)
|
||||||
|
|
||||||
## Permissions
|
## Permissions
|
||||||
One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md)
|
One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md)
|
||||||
|
@ -21,12 +21,14 @@ ms.topic: article
|
|||||||
**Applies to:**
|
**Applies to:**
|
||||||
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
|
||||||
|
This API can do the following actions:
|
||||||
|
|
||||||
- Retrieves a collection of machines that have communicated with Windows Defender ATP cloud on the last 30 days.
|
- Retrieves a collection of machines that have communicated with Windows Defender ATP cloud on the last 30 days.
|
||||||
- Get Machines collection API supports [OData V4 queries](https://www.odata.org/documentation/).
|
- Get Machines collection API supports [OData V4 queries](https://www.odata.org/documentation/).
|
||||||
- The OData's Filter query is supported on: "Id", "ComputerDnsName", "LastSeen", "LastIpAddress", "HealthStatus", "OsPlatform", "RiskScore", "MachineTags" and "RbacGroupId".
|
- The OData's Filter query is supported on: "Id", "ComputerDnsName", "LastSeen", "LastIpAddress", "HealthStatus", "OsPlatform", "RiskScore", "MachineTags" and "RbacGroupId".
|
||||||
- See examples at [OData queries with Windows Defender ATP](exposed-apis-odata-samples.md)
|
|
||||||
|
See examples at [OData queries with Windows Defender ATP](exposed-apis-odata-samples.md)
|
||||||
|
|
||||||
## Permissions
|
## Permissions
|
||||||
|
|
||||||
|
@ -19,9 +19,7 @@ ms.date: 12/08/2017
|
|||||||
|
|
||||||
# Get package SAS URI API
|
# Get package SAS URI API
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease information](prerelease.md)]
|
|
||||||
|
|
||||||
Get a URI that allows downloading of an [investigation package](collect-investigation-package-windows-defender-advanced-threat-protection-new.md).
|
Get a URI that allows downloading of an [investigation package](collect-investigation-package-windows-defender-advanced-threat-protection-new.md).
|
||||||
|
|
||||||
|
@ -14,7 +14,6 @@ manager: dansimp
|
|||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.date: 12/08/2017
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# List Indicators API
|
# List Indicators API
|
||||||
@ -22,9 +21,8 @@ ms.date: 12/08/2017
|
|||||||
**Applies to:**
|
**Applies to:**
|
||||||
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
|
||||||
|
|
||||||
>[!Note]
|
>[!NOTE]
|
||||||
> Currently this API is supported only for AppOnly context requests. (See [Get access with application context](exposed-apis-create-app-webapp.md) for more information)
|
> Currently this API is supported only for AppOnly context requests. (See [Get access with application context](exposed-apis-create-app-webapp.md) for more information)
|
||||||
|
|
||||||
|
|
||||||
|
@ -14,14 +14,12 @@ manager: dansimp
|
|||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.date: 12/08/2017
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Get user related alerts API
|
# Get user related alerts API
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
|
||||||
|
|
||||||
Retrieves a collection of alerts related to a given user ID.
|
Retrieves a collection of alerts related to a given user ID.
|
||||||
|
|
||||||
|
@ -14,15 +14,12 @@ manager: dansimp
|
|||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.date: 12/08/2017
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Get user related machines API
|
# Get user related machines API
|
||||||
|
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
|
||||||
|
|
||||||
Retrieves a collection of machines related to a given user ID.
|
Retrieves a collection of machines related to a given user ID.
|
||||||
|
|
||||||
|
@ -21,8 +21,6 @@ ms.date: 12/05/2018
|
|||||||
**Applies to:**
|
**Applies to:**
|
||||||
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease information](prerelease.md)]
|
|
||||||
|
|
||||||
Learn how you can use Windows Defender ATP to expand the coverage of Windows Information Protection (WIP) to protect files based on their label, regardless of their origin.
|
Learn how you can use Windows Defender ATP to expand the coverage of Windows Information Protection (WIP) to protect files based on their label, regardless of their origin.
|
||||||
|
|
||||||
>[!TIP]
|
>[!TIP]
|
||||||
|
@ -14,7 +14,6 @@ manager: dansimp
|
|||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: conceptual
|
ms.topic: conceptual
|
||||||
ms.date: 12/05/2018
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Information protection in Windows overview
|
# Information protection in Windows overview
|
||||||
|
@ -14,15 +14,11 @@ manager: dansimp
|
|||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.date: 04/24/2018
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Was domain seen in org
|
# Was domain seen in org
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
|
||||||
|
|
||||||
Answers whether a domain was seen in the organization.
|
Answers whether a domain was seen in the organization.
|
||||||
|
|
||||||
|
@ -14,16 +14,13 @@ manager: dansimp
|
|||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.date: 12/08/2017
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Was IP seen in org
|
# Was IP seen in org
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
|
||||||
|
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
|
||||||
|
|
||||||
Answers whether an IP was seen in the organization.
|
Answers whether an IP was seen in the organization.
|
||||||
|
|
||||||
|
@ -14,14 +14,12 @@ manager: dansimp
|
|||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.date: 12/08/2017
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Isolate machine API
|
# Isolate machine API
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease information](prerelease.md)]
|
|
||||||
|
|
||||||
Isolates a machine from accessing external network.
|
Isolates a machine from accessing external network.
|
||||||
|
|
||||||
|
@ -18,11 +18,8 @@ ms.topic: article
|
|||||||
---
|
---
|
||||||
|
|
||||||
# Machine health and compliance report in Windows Defender ATP
|
# Machine health and compliance report in Windows Defender ATP
|
||||||
|
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://wincom.blob.core.windows.net/documents/Windows10_Commercial_Comparison.pdf)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease information](prerelease.md)]
|
|
||||||
|
|
||||||
The machines status report provides high-level information about the devices in your organization. The report includes trending information showing the sensor health state, antivirus status, OS platforms, and Windows 10 versions.
|
The machines status report provides high-level information about the devices in your organization. The report includes trending information showing the sensor health state, antivirus status, OS platforms, and Windows 10 versions.
|
||||||
|
|
||||||
|
@ -14,16 +14,13 @@ manager: dansimp
|
|||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.date: 12/08/2017
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# MachineAction resource type
|
# MachineAction resource type
|
||||||
|
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
|
||||||
|
|
||||||
Method|Return Type |Description
|
Method|Return Type |Description
|
||||||
:---|:---|:---
|
:---|:---|:---
|
||||||
[List MachineActions](get-machineactions-collection-windows-defender-advanced-threat-protection-new.md) | [Machine Action](machineaction-windows-defender-advanced-threat-protection-new.md) | List [Machine Action](machineaction-windows-defender-advanced-threat-protection-new.md) entities.
|
[List MachineActions](get-machineactions-collection-windows-defender-advanced-threat-protection-new.md) | [Machine Action](machineaction-windows-defender-advanced-threat-protection-new.md) | List [Machine Action](machineaction-windows-defender-advanced-threat-protection-new.md) entities.
|
||||||
|
@ -22,7 +22,7 @@ ms.date: 10/18/2018
|
|||||||
**Applies to:**
|
**Applies to:**
|
||||||
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease<EFBFBD>information](prerelease.md)]
|
[!include[Prerelease information](prerelease.md)]
|
||||||
|
|
||||||
Microsoft Cloud App Security (Cloud App Security) is a comprehensive solution that gives visibility into cloud apps and services by allowing you to control and limit access to cloud apps, while enforcing compliance requirements on data stored in the cloud. For more information, see [Cloud App Security](https://docs.microsoft.com/cloud-app-security/what-is-cloud-app-security).
|
Microsoft Cloud App Security (Cloud App Security) is a comprehensive solution that gives visibility into cloud apps and services by allowing you to control and limit access to cloud apps, while enforcing compliance requirements on data stored in the cloud. For more information, see [Cloud App Security](https://docs.microsoft.com/cloud-app-security/what-is-cloud-app-security).
|
||||||
|
|
||||||
|
@ -22,7 +22,7 @@ ms.date: 02/28/2019
|
|||||||
**Applies to:**
|
**Applies to:**
|
||||||
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease<EFBFBD>information](prerelease.md)]
|
[!include[Prerelease information](prerelease.md)]
|
||||||
|
|
||||||
Microsoft Threat Experts is a managed hunting service that provides Security Operation Centers (SOCs) with expert level monitoring and analysis to help them ensure that critical threats in their unique environments don’t get missed.
|
Microsoft Threat Experts is a managed hunting service that provides Security Operation Centers (SOCs) with expert level monitoring and analysis to help them ensure that critical threats in their unique environments don’t get missed.
|
||||||
|
|
||||||
|
@ -21,7 +21,7 @@ ms.topic: conceptual
|
|||||||
**Applies to:**
|
**Applies to:**
|
||||||
- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease<EFBFBD>information](prerelease.md)]
|
[!include[Prerelease information](prerelease.md)]
|
||||||
|
|
||||||
Effectively identifying, assessing, and remediating endpoint weaknesses is pivotal in running a healthy security program and reducing organizational risk. Threat & Vulnerability Management serves as an infrustructure for reducing organizational exposure, hardening endpoint surface area, and increasing organizational resilience.
|
Effectively identifying, assessing, and remediating endpoint weaknesses is pivotal in running a healthy security program and reducing organizational risk. Threat & Vulnerability Management serves as an infrustructure for reducing organizational exposure, hardening endpoint surface area, and increasing organizational resilience.
|
||||||
|
|
||||||
|
@ -15,7 +15,6 @@ manager: dansimp
|
|||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: conceptual
|
ms.topic: conceptual
|
||||||
ms.date: 11/19/2018
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Onboard machines to the Windows Defender ATP service
|
# Onboard machines to the Windows Defender ATP service
|
||||||
|
@ -14,7 +14,6 @@ manager: dansimp
|
|||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.date: 12/08/2017
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Submit or Update Indicator API
|
# Submit or Update Indicator API
|
||||||
@ -22,7 +21,6 @@ ms.date: 12/08/2017
|
|||||||
**Applies to:**
|
**Applies to:**
|
||||||
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease information](prerelease.md)]
|
|
||||||
|
|
||||||
>[!Note]
|
>[!Note]
|
||||||
> Currently this API is supported only for AppOnly context requests. (See [Get access with application context](exposed-apis-create-app-webapp.md) for more information)
|
> Currently this API is supported only for AppOnly context requests. (See [Get access with application context](exposed-apis-create-app-webapp.md) for more information)
|
||||||
|
@ -14,14 +14,11 @@ manager: dansimp
|
|||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.date: 12/08/2017
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Restrict app execution API
|
# Restrict app execution API
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
|
||||||
|
|
||||||
Restrict execution of all applications on the machine except a predefined set (see [Response machine alerts](respond-machine-alerts-windows-defender-advanced-threat-protection.md) for more information)
|
Restrict execution of all applications on the machine except a predefined set (see [Response machine alerts](respond-machine-alerts-windows-defender-advanced-threat-protection.md) for more information)
|
||||||
|
|
||||||
|
@ -19,9 +19,8 @@ ms.date: 09/03/2018
|
|||||||
|
|
||||||
# Advanced hunting API
|
# Advanced hunting API
|
||||||
|
|
||||||
**Applies to:** [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://wincom.blob.core.windows.net/documents/Windows10_Commercial_Comparison.pdf)
|
**Applies to:**
|
||||||
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
[!include[Prerelease information](prerelease.md)]
|
|
||||||
|
|
||||||
This API allows you to run programmatic queries that you are used to running from [Windows Defender ATP Portal](https://securitycenter.windows.com/hunting).
|
This API allows you to run programmatic queries that you are used to running from [Windows Defender ATP Portal](https://securitycenter.windows.com/hunting).
|
||||||
|
|
||||||
|
@ -14,7 +14,6 @@ manager: dansimp
|
|||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.date: 09/24/2018
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Schedule Advanced Hunting using Microsoft Flow
|
# Schedule Advanced Hunting using Microsoft Flow
|
||||||
|
@ -18,7 +18,7 @@ ms.topic: article
|
|||||||
|
|
||||||
# Create custom reports using Power BI (user authentication)
|
# Create custom reports using Power BI (user authentication)
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease information](prerelease.md)]
|
[!include[Prerelease information](prerelease.md)]
|
||||||
|
|
||||||
|
@ -21,8 +21,6 @@ ms.date: 09/24/2018
|
|||||||
**Applies to:**
|
**Applies to:**
|
||||||
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease information](prerelease.md)]
|
|
||||||
|
|
||||||
|
|
||||||
Run advanced queries using PowerShell, see [Advanced Hunting API](run-advanced-query-api.md).
|
Run advanced queries using PowerShell, see [Advanced Hunting API](run-advanced-query-api.md).
|
||||||
|
|
||||||
|
@ -18,9 +18,7 @@ ms.topic: article
|
|||||||
|
|
||||||
# Advanced Hunting using Python
|
# Advanced Hunting using Python
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease information](prerelease.md)]
|
|
||||||
|
|
||||||
Run advanced queries using Python, see [Advanced Hunting API](run-advanced-query-api.md).
|
Run advanced queries using Python, see [Advanced Hunting API](run-advanced-query-api.md).
|
||||||
|
|
||||||
|
@ -14,14 +14,11 @@ manager: dansimp
|
|||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.date: 12/08/2017
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Run antivirus scan API
|
# Run antivirus scan API
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease information](prerelease.md)]
|
|
||||||
|
|
||||||
Initiate Windows Defender Antivirus scan on a machine.
|
Initiate Windows Defender Antivirus scan on a machine.
|
||||||
|
|
||||||
|
@ -14,14 +14,11 @@ manager: dansimp
|
|||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.date: 12/08/2017
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Stop and quarantine file API
|
# Stop and quarantine file API
|
||||||
|
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
[!include[Prerelease<73>information](prerelease.md)]
|
||||||
|
|
||||||
- Stop execution of a file on a machine and delete it.
|
- Stop execution of a file on a machine and delete it.
|
||||||
|
@ -21,7 +21,7 @@ ms.topic: article
|
|||||||
**Applies to:**
|
**Applies to:**
|
||||||
- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease<EFBFBD>information](prerelease.md)]
|
[!include[Prerelease information](prerelease.md)]
|
||||||
|
|
||||||
## Before you begin
|
## Before you begin
|
||||||
Ensure that your machines:
|
Ensure that your machines:
|
||||||
|
@ -17,10 +17,8 @@ ms.topic: article
|
|||||||
---
|
---
|
||||||
|
|
||||||
# Indicator resource type
|
# Indicator resource type
|
||||||
|
**Applies to:**
|
||||||
**Applies to:** - Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease information](prerelease.md)]
|
|
||||||
|
|
||||||
Method|Return Type |Description
|
Method|Return Type |Description
|
||||||
:---|:---|:---
|
:---|:---|:---
|
||||||
|
@ -21,7 +21,7 @@ ms.topic: conceptual
|
|||||||
**Applies to:**
|
**Applies to:**
|
||||||
- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease<EFBFBD>information](prerelease.md)]
|
[!include[Prerelease information](prerelease.md)]
|
||||||
|
|
||||||
>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-portaloverview-abovefoldlink)
|
>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-portaloverview-abovefoldlink)
|
||||||
|
|
||||||
|
@ -14,14 +14,12 @@ manager: dansimp
|
|||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.date: 12/08/2017
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Release machine from isolation API
|
# Release machine from isolation API
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
|
||||||
|
|
||||||
Undo isolation of a machine.
|
Undo isolation of a machine.
|
||||||
|
|
||||||
|
@ -14,14 +14,11 @@ manager: dansimp
|
|||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.date: 12/08/2017
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Remove app restriction API
|
# Remove app restriction API
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
|
||||||
|
|
||||||
Enable execution of any application on the machine.
|
Enable execution of any application on the machine.
|
||||||
|
|
||||||
|
@ -14,16 +14,12 @@ manager: dansimp
|
|||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.date: 12/08/2017
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Update alert
|
# Update alert
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
|
||||||
|
|
||||||
|
|
||||||
[!include[Prerelease<73>information](prerelease.md)]
|
|
||||||
Update the properties of an alert entity.
|
Update the properties of an alert entity.
|
||||||
|
|
||||||
## Permissions
|
## Permissions
|
||||||
|
@ -19,7 +19,8 @@ ms.date: 11/28/2018
|
|||||||
|
|
||||||
# Windows Defender ATP Public API
|
# Windows Defender ATP Public API
|
||||||
|
|
||||||
**Applies to:** [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://wincom.blob.core.windows.net/documents/Windows10_Commercial_Comparison.pdf)
|
**Applies to:**
|
||||||
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
> Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-exposedapis-abovefoldlink)
|
> Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-exposedapis-abovefoldlink)
|
||||||
|
|
||||||
|
@ -14,10 +14,11 @@ manager: dansimp
|
|||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.date: 12/08/2017
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# User resource type
|
# User resource type
|
||||||
|
**Applies to:**
|
||||||
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
Method|Return Type |Description
|
Method|Return Type |Description
|
||||||
:---|:---|:---
|
:---|:---|:---
|
||||||
|
@ -19,11 +19,16 @@ ms.topic: conceptual
|
|||||||
|
|
||||||
# What's new in Windows Defender ATP
|
# What's new in Windows Defender ATP
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
Here are the new features in the latest release of Windows Defender ATP as well as security features in Windows 10 and Windows Server.
|
Here are the new features in the latest release of Windows Defender ATP as well as security features in Windows 10 and Windows Server.
|
||||||
|
|
||||||
## April 2019
|
## April 2019
|
||||||
|
The following capability is generally available (GA).
|
||||||
|
|
||||||
|
- [Microsoft Defender ATP API](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/use-apis) <BR> Microsoft Defender ATP exposes much of its data and actions through a set of programmatic APIs. Those APIs will enable you to automate workflows and innovate based on Windows Defender ATP capabilities.
|
||||||
|
|
||||||
|
|
||||||
### In preview
|
### In preview
|
||||||
The following capabilities are included in the April 2019 preview release.
|
The following capabilities are included in the April 2019 preview release.
|
||||||
|
|
||||||
|
Reference in New Issue
Block a user